Live data from Hacker News

GDPR penalty for passing on of IP address to Google by using Google Fonts

rewis.io

631–640 of 656 posts

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#631
post #307

Earlier quoted context omitted.

Under the GDPR, an IP address is personally identifiable data, so you can't leak it. And for someone with masses of extra data like Google it is enough to identify who is doing the browsing, so this isn't some crazy overreach.

But GP has a point: An IP address (together with a timestamp) may be used to identify you a person but if it's not connected to actual personal data (e.g. what website you visited), "leaking" it to Google doesn't provide Google with any data about you. I mean, IP address ranges are publicly known. If I now run a `for` loop over all IPv4 addresses and write them to my HDD, am I suddenly illegally storing personal data…

> If I now run a `for` loop over all IPv4 addresses and write them to my HDD, am I suddenly illegally storing personal data of all the people behind those IP addresses

That's actually a good point. The IPv4 space is pretty limited. I guess the GDPR law makes it PII if you bundle both the IP with an action made by that IP (e.g. that IP visited that website).

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#632
post #551

Earlier quoted context omitted.

>> This is exactly what happened... Not quite? Wouldn't the users browser have sent its own IP address to Google? That's different that "forwarding" it, and it may not even be enough for Google to connect the user to that site.

This argument was tried in the Fashion ID case. A company had inserted Facebook Like buttons on the web page, and argued that it was not responsible for the ensuing disclosure of personal data (such as IP addresses or possible tracking cookies) to Facebook. See, it was the browser and not the website operator that disclosed the data, and the website operator never had access to the data in the browser in the first pl…

Thanks, that was a very good explanation with legal backing.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#633

Earlier quoted context omitted.

Let's assume Google can identify the user but doesn't get a referrer. So what? The only information Google receives is that some user visited some unknown website at a particular time. How exactly would that lead to Google increasing its profits?

They know users activity hours better that way. At scale that is valuable data.

But that's still not personal data.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#634
post #565

Earlier quoted context omitted.

But GP has a point: An IP address (together with a timestamp) may be used to identify you a person but if it's not connected to actual personal data (e.g. what website you visited), "leaking" it to Google doesn't provide Google with any data about you. I mean, IP address ranges are publicly known. If I now run a `for` loop over all IPv4 addresses and write them to my HDD, am I suddenly illegally storing personal data…

The court judgement addresses this exact point. There are previous judgements ( Breyer v Bundesrepublik Deutschland ) that establish that dynamic IP addresses are personal data. There are reasonable means to identify the data subject with the help of third parties, such as the ISP. “For this it is sufficient that the defendant has the abstract means for identification of the person behind the IP address. Whether the…

You're missing the point (and mischaracterizing the court decisions): An IP address by itself (without any additional information, e.g. the URL of the website requested by that IP address) cannot possibly be personal data, as was illustrated by my "for loop" example.

The present court case and also the one you're referring to (Breuer v. Bundesrepublik Deutschland[0]) do not say anything to the contrary. They were concerned with situations where there is additional data that could be used e.g. to build a user profile. For instance, the Bundlesgerichtshof judgment addressed the question of "whether dynamic IP addresses of website visitors constitute personal data for website operators" [0] (which clearly know which website the visitor visited and therefore possess additional data about the visitor).

[0]: https://medium.com/golden-data/breyer-are-dynamic-ip-address...

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#635
What's next? Someone coming after you, because your have their IP in your server logs?

I understand the privacy sentiment, but I find this the opposite of how you beat a giant. The proper way for Germany and the rest of Europe should be the creation of a thriving environment of viable, privacy-aware FAANG competitors. Not putting barriers in every which way.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#636
post #577

Earlier quoted context omitted.

This will also happen if I place a link on my site that does not clearly warn the user that it leads to a non EU website. User clicks it, and his IP address gets disclosed. Really, if you participate in the World Wide Web, of course your computer’s address will be visible to others, and you can not always control it. Like driving on the Autobahn. People will be able to see you. It’s part of life.

GDPR differentiates between functional necessary and non-functional necessary parts. And again technical nit-picking do not matter, but user intend does. Similar that side you link to would also need to be GDPR compliant (or not provide service in EU countries). The problem with google fonts is that the side which loads them agrees in your stead without your permission to google collecting your data and using it for…

Ok, good points.

What about embedding a Google Map? I see those even on websites of German courts.

Are those allowed because the embed is needed functionally?

Or are they not, because you could instead use a cached image of the map and switch to a “live” connection to Google’s map server only when the user actually tries to move or zoom the map (and after displaying a consent pop up)?

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#637
post #565

Earlier quoted context omitted.

The court judgement addresses this exact point. There are previous judgements ( Breyer v Bundesrepublik Deutschland ) that establish that dynamic IP addresses are personal data. There are reasonable means to identify the data subject with the help of third parties, such as the ISP. “For this it is sufficient that the defendant has the abstract means for identification of the person behind the IP address. Whether the…

You're missing the point (and mischaracterizing the court decisions): An IP address by itself (without any additional information, e.g. the URL of the website requested by that IP address) cannot possibly be personal data, as was illustrated by my "for loop" example. The present court case and also the one you're referring to (Breuer v. Bundesrepublik Deutschland[0]) do not say anything to the contrary. They were con…

I can't agree, but maybe this is semantics :)

For something to be personal data, it must be information that relates to an identifiable natural person. There are two criteria here: (1) it must relate to a natural person, and (2) that person must be identifiable.

Your “loop over IP all addresses”example does not involve personal data because the information doesn't relate to anyone – it is just a list of numbers. Even if it were to relate to individuals, no court would order an ISP to disclose information about corresponding subscribers for such generated IP addresses. Then, the identifiability argument in Breyer cannot work.

In contrast, an IP address that is part of an IP packet received by a server clearly relates to the person sending the packet, if there is such a person. And, with the help of third parties, the person on the other end of the connection is reasonably likely to be identifiable. This does not depend on the website operator having any additional information such as cookie identifiers, other than the date. To avoid confusion, let me quote the relevant part from Breyer:

> 49. Having regard to all the foregoing considerations, the answer to the first question is that [Art 4(1) of the GDPR] must be interpreted as meaning that a dynamic IP address registered […] when a person accesses a website […] constitutes personal data within the meaning of that provision, in relation to that [website] provider, where the latter has the legal means which enable it to identify the data subject with additional data which the internet service provider has about that person.

The only additional data involved here is that held by the ISP, not by the website. That the judgement scopes its conclusion to website providers must be understood not as a limiting factor (as in: IPs can be personal data only for website providers), but as a contrast to the uncontested observation that IPs clearly are personal data for ISPs.

An IP address that relates to an identifiable person is personal data by itself. Thus, its mere disclosure to a third party without a legal basis is a breach of the GDPR. The article you linked highlights the “absolute vs relative” identifiability discussion, but this reasoning holds even under the “relative” standpoint because Google too is a website operator who has the same reasonably likely means for identification as the original website operator, if not substantially better means due to its trove of other data it can correlate with the IP address.

In this LG München case, the court determined that sharing this data with Google was illegal, regardless of whether there is any additional data. It is, in a sense, a very formal argument, that doesn't consider it necessary to dive into specific fact patterns (that's the abstract vs concrete means part quoted in my previous comment). The court did consider the impact of Google's tracking abilities in calculating damages, though.

To summarize my disagreement with your comment: (1) I assert that an IP address by itself can be personal data for a website operator (such as the defendant or Google), per the Breyer argument. (2) The LG München judgement in this Google Fonts case is not concerned about additional data when considering the legality of processing. (3) Additional knowledge held by the website operator is irrelevant for both this case and the Breyer judgement. Since a negative is difficult to prove but a positive can be shown by a single example, could you please point out the paragraphs in the Google Fonts case[1] or the ECJ's Breyer judgement[2] where I'm mistaken for disagreements 2 or 3?

[1] https://rewis.io/urteile/urteil/lhm-20-01-2022-3-o-1749320/

[2] https://curia.europa.eu/juris/document/document.jsf?docid=18...

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#638
post #538
post #128

Earlier quoted context omitted.

> In fact, since in parallel to the question of your legal basis under GDPR, you also have to comply with the cookie provision from the e-Privacy Directive, where there is no "legitimate interest" exception to the requirement to ask for consent, you will have to ask for consent anyway (as Instagram embeds place cookies). I don't think that's true. The cookie provision is misunderstood when you think you have to ask f…

Careful. That is an 100% unofficial site. It is not chartered or funded by the EU. The linked article is from “Richie Koch”an editor working on human rights stories who wrote the article on behalf of Proton VPN, which runs the GDPR.eu site as a content marketing scheme. The linked article is not the law and not official guidance, though it provides a reasonably good summary. Everything sqrt2 says in the comments is e…

Fair point. And thanks. I think now that my position - while how it should be, consistent with the GDPR and repeated at multiple places - is possibly not in line with a court decision from 2019 or so, that interpreted the e-Privacy Directive in a wrong way imho, and at the very least might depends on local practice of how EU "law" is applied. So you two are probably right.

Ridiculous to govern non-privacy relevant tech usage like this. I still think that's illegal where I live. Regardless, let's hope the e-Privacy Regulation or future court decisions solve this.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#639
post #116

Curious how useful is an IP address with a simple HTTP get request? As long as a sane Referer-Policy is set, the Referer won't be sent. Sure there's a lot more to browser fingerprinting but with just an HTTP request, all the data that would be known from it is the language and the user agent. Both of which are not unique data points and shared by thousands of other users. No cookies either in this case of Google Font…

Consider the following scenario: You are logged in to to google and so are your family members. You visit YouTube.com from IP X with device (user agent) Y. Your family member visits YouTube.com from IP X with device Z. Google Fonts gets a request via the API key of mydomain.de from IP X and device Y. Google now knows that you visited mydomain.de Edit: I stand corrected that Google Fonts doesn't use an API key. I susp…

Several people and devices could be shared by the same IP though, either who are on the same network or in the vicinity of the same mobile mast (or in the same mall or restaurant)... that's why IP often isn't used as conclusive evidence that you are the same person just because you are on the same IP.

Re: GDPR penalty for passing on of IP address to Google by using Google Fonts

#640
post #533

Earlier quoted context omitted.

> So everyone showing youtube videos would be affected unless users also start agreeing to IP exposure Yes, and that's a good thing! A web page should only communicate with the server i've reached, there should be zero third-party involved unless i explicitly consent. That for example tag can use an arbitrary URL is explained by the fact that back in the day storage/bandwidth was expensive. The same is true for video…

Are you sure about the „explicitly“ part? I think it in certain cases, implicit consent should be enough, e.g. when a payment processor is contacted from a website. Even if you were running your own payment gateway, the user of your shop should be aware that the website will have to share information with their bank or credit card company. I think sharing data with third parties should not be easier than offline, but…

You are correct. However me simply visiting a homepage (service) does not require communicating my data to third parties, and doing so is not in the legitimate interest of any of the first parties involved. In this case it would fall under the obligation of explicit content.
Post reply on HN